# Logstash 'compile\_imperative' error

**URL:** <https://discuss.elastic.co/t/logstash-compile-imperative-error/276625>\
**Category:** Logstash\
**Created:** [June 22, 2021, 9:03am UTC](https://discuss.elastic.co/t/logstash-compile-imperative-error/276625 "2021-06-22T09:03:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Michael\_Dylan\_McAloo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_dylan_mcaloo/32/80928_2.png) [@Michael\_Dylan\_McAloo](https://discuss.elastic.co/u/Michael_Dylan_McAloo)\
**Post date:** [June 22, 2021, 9:03am UTC](https://discuss.elastic.co/t/logstash-compile-imperative-error/276625/1 "2021-06-22T09:03:39Z")

</div>

Hi,  
I have Logstash to pick up Snort Alerts, but i have had this error and i don't know why.

Error:

```auto
logstash | [2021-06-22T08:55:53,809][ERROR][logstash.agent] Failed to execute action {:action=>LogStash::PipelineAction::Create/pipeline_id:main, :exception=>"LogStash::ConfigurationError", :message=>"Expected one of [\\t\\r\\n], \"#\", \"{\", \"}\" at line 9, column 67 (byte 190) after filter {\n dissect { mapping => { \"message\" => \"%{ts} [%{trash}] [%{fd1}] \"", :backtrace=>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:32:in `compile_imperative'", "org/logstash/execution/AbstractPipelineExt.java:184:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:69:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:47:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:52:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:367:in `block in converge_state'"]}

```

Logstash.conf file:

```auto
input {
    file {
        path => "/var/log/snort/alert_fast.txt"
        start_position => "beginning"
    }
}

filter {
  dissect { mapping => { "message" => "%{ts} [%{trash}] [%{fd1}] "%{alert}" [%{fd2}} %{ip_ori}:%{port_ori} %{fd3} %{ip_dest}:%{port_dest}" }>

output {
    elasticsearch {
        hosts => "http://localhost:9200"
        index => "logstash-snort3a"
    }
    stdout { }
}

```

---

<div class="post-metadata">

**Author:** ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)\
**Post date:** [June 22, 2021, 9:31am UTC](https://discuss.elastic.co/t/logstash-compile-imperative-error/276625/2 "2021-06-22T09:31:20Z")

</div>

Hi,

You have to place a backslash in front of the quotes around {alert}. They split your regex.

Cad.

---

<div class="post-metadata">

**Author:** ![Michael\_Dylan\_McAloo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_dylan_mcaloo/32/80928_2.png) [@Michael\_Dylan\_McAloo](https://discuss.elastic.co/u/Michael_Dylan_McAloo)\
**Post date:** [June 22, 2021, 9:33am UTC](https://discuss.elastic.co/t/logstash-compile-imperative-error/276625/3 "2021-06-22T09:33:32Z")

</div>

I just realized it , i used this solution:

```auto
dissect { mapping => { "message" => '%{ts} [%{trash}] [%{fd1}] "%{alert}" [%{fd2}} %{ip_ori}:%{port_ori} %{fd3} %{ip_dest}:%{port_dest}' }}

```

Thanks 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 20, 2021, 9:34am UTC](https://discuss.elastic.co/t/logstash-compile-imperative-error/276625/4 "2021-07-20T09:34:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
